IP Library Granted Patent US 11,849,049
Granted Patent B2
US 11,849,049 · App. 17/295,538 · Granted Dec 19, 2023

Circuit chip and a method of operating it

Inventors: Sébastien Chapellier (Meudon, FR); Mario Lucas Ranti (Meudon, FR); Jervis Wang-Zw (Meudon, FR); Yong Jie Foo (Meudon, FR)
Assignee: THALES DIS FRANCE SAS
H04L9/3263B42D25/305G06F21/572H04L9/088H04L9/30H04L9/3247B42D25/24G06F2221/033G06Q30/018G06Q50/265G06Q2220/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,849,049
App. No.
17/295,538
Granted
Dec 19, 2023
Kind
B2
Abstract

Secure patching of an operating system of the integrated circuit chip. A patch server encrypts a patch to the operating system of the integrated circuit chip and transmits the encrypted patch to an issuing-authority server. The issuing-authority server appends the encrypted patch into a digital certificate in an extension to the digital certificate and transmits the digital certificate including the encrypted patch to a terminal. The terminal transmits the digital certificate the integrated circuit chip. The integrated circuit chip recovers the extension to the second digital certificate and decrypts the extension using a decryption key of the manufacturer of the integrated circuit chip thereby recovering the patch to the operating system of the integrated circuit chip and installs the patch into the operating system of the integrated circuit chip.

Claims (36)

1. A method for operating an integrated circuit chip comprising a first digital certificate of an issuing authority, a patch server, an issuing-authority server, and a terminal to securely patch an operating system of the integrated circuit chip, the method comprising:

operating the patch server to encrypt a patch to the operating system of the integrated circuit chip;

operating the patch server to transmit the encrypted patch to the issuing-authority server;

operating the issuing-authority server to append the encrypted patch into a second digital certificate of the issuing authority in an extension to the second digital certificate;

operating the issuing-authority server to transmit the second digital certificate including the encrypted patch to the terminal;

operating the terminal to communicate with the integrated circuit chip upon presentation of the integrated circuit chip to the terminal;

operating the terminal to transmit the second digital certificate including the encrypted patch to the integrated circuit chip;

operating the integrated circuit chip to unpack the second digital certificate including the encrypted patch to recover the extension to the second digital certificate; and

operating the integrated circuit chip to verify that the extension to the second digital certificate corresponds to the operating system of the integrated circuit chip;

and if the extension is verified to correspond to the operating system of the integrated circuit chip, to decrypt the extension to the second digital certificate thereby recovering the patch to the operating system of the integrated circuit chip, and installing the patch into the operating system of the integrated circuit chip.

2. The method according to claim 1 , further comprising:

operating the patch server to digitally sign the encrypted patch; and

operating the integrated circuit chip to verify the digital signature of encrypted patch prior to installing the patch into the operating system of the integrated circuit chip.

3. The method of claim 2 , further comprising a preliminary step of installing a private key of the manufacturer of the integrated circuit chip into the integrated circuit chip; and wherein the patch server encrypts the patch using the public key corresponding to the private key of the manufacturer of the integrated circuit chip, and wherein the integrated circuit chip decrypts the extension to the digital certificate using the private key of the manufacturer.

4. The method of claim 2 , further comprising a preliminary step of installing a secret key of the manufacturer of the integrated circuit chip into the integrated circuit chip; and wherein the patch server encrypts the patch using the secret key corresponding to the secret key of the manufacturer of the integrated circuit chip, and wherein the integrated circuit chip decrypts the extension to the digital certificate using the secret key of the manufacturer.

5. The method of claim 1 , further comprising a preliminary step of installing a private key of the manufacturer of the integrated circuit chip into the integrated circuit chip; and wherein the patch server encrypts the patch using the public key corresponding to the private key of the manufacturer of the integrated circuit chip, and wherein the integrated circuit chip decrypts the extension to the digital certificate using the private key of the manufacturer.

6. The method of 1 claim 1 , further comprising a preliminary step of installing a secret key of the manufacturer of the integrated circuit chip into the integrated circuit chip; and wherein the patch server encrypts the patch using the secret key corresponding to the secret key of the manufacturer of the integrated circuit chip, and wherein the integrated circuit chip decrypts the extension to the digital certificate using the secret key of the manufacturer.

7. The method of claim 1 wherein the second digital certificate of the issuing authority is a link certificate that links to the first certificate of the certificate authority stored on the integrated circuit chip.

8. The method of claim 1 wherein the link certificate is a country verifying certificate authority link certificate and the extension to the link certificate contains an object identifier indicating the manufacturer of the integrated circuit chip as having originated the extension to the link certificate.

9. The method of claim 1 wherein the integrated circuit chip is embedded in an electronic security document.

10. The method of claim 1 wherein the electronic security document is a machine readable travel document.

11. An integrated circuit chip comprising:

a processor; and

a memory connected to the processor and containing instructions executable by the processor including an operating system; and

instructions to cause the processor to: receive a digital certificate from a patch server via a verifier terminal, the digital certificate including an extension containing an encrypted patch for the operating system;

unpack the digital certificate thereby recovering the extension to the digital certificate;

verify that the extension to the digital certificate corresponds to the operating system of the integrated circuit chip; and when the extension is verified to correspond to the operating system of the integrated circuit chip, to decrypt the extension to the digital certificate thereby recovering the patch to the operating system of the integrated circuit chip, and installing the patch into the operating system of the integrated circuit chip.

12. The integrated circuit chip of claim 11 where the instructions of the patch loader further comprise instructions to cause the processor to verify the digital signature of encrypted patch prior to installing the patch into the operating system of the integrated circuit chip.

13. The integrated circuit chip of claim 12 wherein the memory further includes a private key of the manufacturer of the integrated circuit chip; and wherein the patch is encrypted using the public key corresponding to the private key of the manufacturer of the integrated circuit chip, and wherein the instructions further comprise instructions to cause the processor to decrypt the extension to the digital certificate using the private key of the manufacturer.

14. The integrated circuit chip of claim 12 wherein the memory further includes a secret key of the manufacturer of the integrated circuit chip; and wherein the patch is encrypted using the shared secret key; and wherein the instructions further comprise instructions to cause the processor to decrypt the extension to the digital certificate using the shared secret key of the manufacturer.

15. The integrated circuit chip of claim 11 wherein the memory further includes a private key of the manufacturer of the integrated circuit chip; and wherein the patch is encrypted using the public key corresponding to the private key of the manufacturer of the integrated circuit chip, and wherein the instructions further comprise instructions to cause the processor to decrypt the extension to the digital certificate using the private key of the manufacturer.

16. The integrated circuit chip of claim 11 wherein the memory further includes a secret key of the manufacturer of the integrated circuit chip; and wherein the patch is encrypted using the shared secret key; and wherein the instructions further comprise instructions to cause the processor to decrypt the extension to the digital certificate using the shared secret key of the manufacturer.

17. The integrated circuit chip of claim 11 wherein the second digital certificate of the issuing authority is a link certificate that links to the first certificate of the certificate authority stored on the integrated circuit chip.

18. The integrated circuit chip of claim 17 wherein the link certificate is a country verifying certificate authority link certificate and the extension to the link certificate contains an object identifier indicating the manufacturer of the integrated circuit chip as having originated the extension to the link certificate.

19. The integrated circuit chip of claim 11 wherein the integrated circuit chip is embedded in an electronic security document.

20. The integrated circuit chip of claim 11 wherein the electronic security document is a machine readable travel document.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 064870/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2023
From: CHAPELLIER, SEBASTIEN; RANTI, MARIO LUCAS; WANG-ZW, JERVIS; FOO, YONG JIE
To: THALES DIS (SINGAPORE) PTE LTD
Reel/Frame 064840/0986 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2023
From: THALES DIS (SINGAPORE) PTE LTD
To: THALES DIS FRANCE SA
Reel/Frame 064841/0277 →
Priority Claims (1)
EP 18306538 · Nov 21, 2018 · regional
Continuity (1)
Related Publication 20220014387A1 · Jan 13, 2022